# CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation, CISA KEV)

> N-able N-central on-premises RMM platform contains a critical pre-authentication static code injection vulnerability (CWE-96) rated CVSS 10.0, allowing unauthenticated remote attackers to execute arbitrary code on the underlying operating system. CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog on September 8, 2026, confirming active in-the-wild exploitation. Huntress reported at least one customer instance compromised before the patch shipped. The vulnerability affects all builds prior to 2026.3.1.14 across release lines 2025.4 through 2026.3, marking the fourth emergency hotfix in five weeks for the platform.

- **Published:** 2026-09-09T00:00:00Z
- **Last reviewed:** 2026-09-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2415
- **ID:** TL-2026-2415
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-86218

## Description

CVE-2026-86218 is a pre-authentication remote code execution vulnerability in N-able N-central, an on-premises remote monitoring and management (RMM) platform widely deployed by Managed Service Providers (MSPs) and enterprise IT organizations. The vulnerability is classified as a static code injection (CWE-96) — improper neutralization of directives in statically saved, executable code — enabling attackers with network access to an exposed N-central HTTP administration interface to achieve unrestricted, remote code execution on the server's operating system without authentication or user interaction.

The flaw was discovered and reported through N-able's responsible disclosure program. N-able released Hotfix 4 (build 2026.3.1.14) on September 5-6, 2026 to address it. Huntress independently confirmed at least one compromised on-premises instance on September 4, 2026 — a server that was fully patched up to the then-current hotfix level — though rotated logs prevented definitive attribution to a specific exploit chain. watchTowr successfully reproduced the exploit and confirmed the pre-auth RCE capability. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, mandating that federal civilian agencies apply mitigations by September 11, 2026 under Binding Operational Directive (BOD) 26-04, with forensic triage required for any exposed systems.

N-central is architecturally a Java-based application fronted by an Envoy edge proxy (TCP 8443 by default) passing requests to Jetty, with legacy SOAP API endpoints at /dms/services/ServerUI and /dms/services/ServerMMS. The platform's role as MSP management infrastructure makes it a high-value target — a compromised N-central server provides immediate administrative access to all downstream managed endpoints via built-in remote-control features (Take Control), remote scripting, and software deployment capabilities. The Shadowserver Foundation estimated approximately 1,500 internet-facing N-central instances were potentially exploitable.

Post-exploitation activity observed by Huntress and other responders includes: creation of unauthorized administrative accounts with .invalid email suffixes, deployment of Cloudflare tunnels (cloudflared) as persistent backdoor channels, abuse of the built-in MSP Support account for Take Control sessions, process masquerading (svchost.exe placed in user Documents folders), targeted reconnaissance on Domain Controllers, and use of EDR evasion tooling. The compromise cascade risk is severe: a single N-central server breach can expose hundreds or thousands of downstream client environments to ransomware deployment, data theft, and persistent network access.

This vulnerability is the latest in a cascade of N-central security disclosures. Prior hotfixes in August-September 2026 addressed CVE-2026-18556 and CVE-2026-18577 (authentication bypass, CVSS 8.2, exploited in the wild from August 1, 2026), followed by CVE-2026-86206 (semiolon/Forwarded header parsing discrepancy between Envoy and Jetty, CVSS 6.9) and CVE-2026-86207 (UserTwoFactorLogin authentication bypass via built-in user IDs 1, 50, and 51, CVSS 7.7), both discovered by Rapid7 Labs. CVE-2026-86218 is distinct in requiring no prior access whatsoever — a single HTTP request to an exposed port is sufficient for full compromise.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1133 External Remote Services
- T1543 Create or Modify System Process
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1057 Process Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1572 Protocol Tunneling
- T1219 Remote Access Tools

## Sources

- [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-86218](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [NVD Detail — CVE-2026-86218 (CVSS 10.0 / 9.8)](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-86218)
- [The Hacker News — N-able N-central Pre-Auth RCE Flaw Added to CISA KEV](https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html)
- [Cybersecuritynews — N-able N-central RCE Vulnerability](https://cybersecuritynews.com/n-able-n-central-rce/)
- [Meterpreter.org — CVE-2026-86218 Technical Breakdown](https://meterpreter.org/cve-2026-86218-n-central-vulnerability-rce/)
- [Rapid7 — CVE-2026-86206 / CVE-2026-86207 Authentication Bypass Analysis](https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/)
- [Huntress — N-able Vulnerability Exploitation Investigation](https://www.huntress.com/blog/n-able-vulnerability-exploitation)
- [Horizon3.ai — N-able N-central: From N-days to 0-days (Attack Surface Research)](https://horizon3.ai/attack-research/attack-blogs/n-able-n-central-from-n-days-to-0-days/)
- [N-able Status — N-central 2026.3 Hotfix 4 / CVE-2026-86218](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/)
- [N-able Release Notes — N-central 2026.3 HF4](https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm)
- [CISA BOD 26-04 Implementation Guidance](https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk)
- [Sophos — N-able N-central Exploitation Results in RMM Tool Deployment](https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment)
- [Shadowserver Foundation — Internet-facing N-central Instance Count](https://www.shadowserver.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2415
